analyzing-active-directory-acl-abuse

Pass

Audited by Gen Agent Trust Hub on Mar 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill performs legitimate security analysis of Active Directory environments. It uses the ldap3 library to programmatically inspect security descriptors on domain objects.
  • [COMMAND_EXECUTION]: The agent.py script accepts sensitive credentials (username and password) via command-line arguments. While this is common for CLI tools, users should be aware that passwords passed this way may be visible in process listings or shell history.
  • [EXTERNAL_DOWNLOADS]: The skill relies on the ldap3 Python package, which is a well-known and trusted library for LDAP operations.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 15, 2026, 12:26 AM